Automated Exception Handling for Data Security and Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data loss prevention systems often prohibit actions that should be exceptions, leading to administrative burdens and delays, particularly in healthcare where timely access to patient records is crucial, due to their restrictive nature.
Innovation Solution
Implementing automated exception handling that determines whether a user with elevated rights can perform a prohibited action based on their role, allowing exceptions without manual administrator approval for actions like saving patient records to encrypted media or emailing protected health information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data loss prevention systems prohibit actions involving protected data, then data security is improved, but operational efficiency deteriorates due to administrative burdens and delays
Solution Approach 1:
The patent segments the exception handling process into automated evaluation components that assess user roles, action types, and data sensitivity levels independently, then combine these assessments to determine whether to grant exceptions. This segmentation allows the system to maintain strict security protocols while efficiently processing exception requests without requiring manual administrative review for every case.
Solution Approach 2:
The patent implements preliminary action by pre-defining role-based policies and exception criteria before prohibited actions occur. The system evaluates exception requests against pre-established rules regarding user roles, action types, and data categories, enabling automated decision-making that maintains security while improving operational efficiency by eliminating ad-hoc administrative reviews.
2Reliability
If manual administrator approval is required for exceptions, then data security control is improved, but time consumption increases due to administrative delays
Solution Approach 1:
The patent implements self-service by enabling the exception handling system to automatically evaluate and process exception requests based on pre-defined policies regarding user roles, action types, and data sensitivity. The system serves itself by making authorization decisions without requiring manual administrator intervention, thereby maintaining security control while eliminating time-consuming administrative delays.
Solution Approach 2:
The patent incorporates feedback mechanisms where the automated exception handling system continuously evaluates exception requests against established security policies, learns from administrative decisions, and refines its authorization logic. This feedback loop maintains security control by ensuring policies are consistently applied while reducing time consumption through automated, policy-based decision-making.
3Reliability
If restrictive data loss prevention measures are implemented, then data security is improved, but ease of operation deteriorates due to limitations on legitimate actions
Solution Approach 1:
The patent applies dynamics by implementing a flexible exception handling system that adapts authorization decisions based on real-time evaluation of user roles, action types, and data sensitivity levels. Rather than applying static restrictive measures uniformly, the system dynamically adjusts permissions based on the specific context of each request, maintaining data security while improving ease of operation for legitimate actions.
Solution Approach 2:
The patent implements local quality by applying different levels of restriction and exception criteria to different user roles, action types, and data categories. Instead of uniform restrictive measures, the system tailors security controls and exception policies to the specific local context of each request, ensuring data security is maintained while minimizing unnecessary operational limitations.
Data Source
AI summary
Methods, apparatuses, and computer program products are provided for exception handling. A method may include detecting attempted performance of a prohibited action involving protected data. The method may further include determining based at least in part on a role associated with a user associated with the prohibited action whether the user has elevated rights permitting performance of the prohibited action. The method may additionally include permitting an exception allowing performance of the prohibited action only in an instance in which it is determined that the user does have elevated rights permitting performance of the prohibited action. The method may also include prohibiting performance of the prohibited action in an instance in which it is determined that the user does not have elevated rights permitting performance of the prohibited action. Corresponding apparatuses and computer program products are also provided.


